Singapore-based cryptocurrency platform Phemex was forced to pause some of its operations on Thursday after a suspected cyberattack led to the theft of more than $69 million in digital coins.
Impersonating a well-known brand is an easy way for scammers to get people to click their malicious links. Here's what to watch for.
The modern workplace has undergone a seismic transformation over recent years, with hybrid work becoming the norm and businesses rapidly adopting cloud-based Software-as-a-Service (SaaS)...
Crooks pwning crooks – Hackers exploit script kiddies with XWorm RAT, compromising 18,000+ devices globally and stealing sensitive…
Zyxel is warning that a bad security signature update is causing critical errors for USG FLEX or ATP Series firewalls, including putting the device into a boot loop. [...]
These are the best password managers for businesses on the market, whether you own a small business or need an enterprise-grade security solution.
The U.S. Department of Justice (DoJ) on Thursday indicted two North Korean nationals, a Mexican national, and two of its own citizens for their alleged involvement in the ongoing fraudulent...
Microsoft has reminded Windows administrators that driver synchronization in Windows Server Update Services (WSUS) will be deprecated on April 18, 90 days from now. [...]
Amazon Web Services has launched its Cyber Education Grant Program in the UK
How to uncover potential threats and eliminate critical risks in your cloud environment.
Hidden text salting is a simple yet effective technique for bypassing email parsers, confusing spam filters, and evading detection engines that rely on keywords. Cisco Talos observed an increase...
2025-01-23 • Lumen • Black Lotus Labs • elf.seaspy Open article on Malpedia
The SANS Institute collaborates to form the Southeastern Cyber Workforce Alliance (SECWA), establishing a definitive pathway to rewarding... The post SANS Institute launches SECWA to empower...
The U.S. House Committee on Homeland Security held on Wednesday a hearing to examine cybersecurity threats to the... The post US House Committee calls for offensive cyber strategies in response to...
Following the release of an EU action plan by the European Commission last week, aimed at enhancing the... The post ENISA addresses proposed role to safeguard cybersecurity of health sector in EU...
2025-01-20 • JPCERT/CC • Hayato Sasaki Open article on Malpedia
Google has launched a new feature called Identity Check for supported Android devices that locks sensitive settings behind biometric authentication when outside of trusted locations. "When you...
2025-01-23 • ThreatMon • Aziz Kaplan, ThreatMon, ThreatMon Malware Research Team • elf.helldown Open article on Malpedia
Security researchers have discovered an arbitrary account takeover flaw in Subaru's Starlink service that could let attackers track, control, and hijack vehicles in the United States, Canada, and...
A North Korean threat group has been using a technique called RID hijacking that tricks Windows into treating a low-privileged account as one with administrator permissions. [...]
Crazy Evil, a group of crypto scammers, exploit NFTs and cryptocurrencies with malware targeting influencers and tech professionals
XSS (Cross-site Scripting) vulnerability has been found in Eura7 CMSmanager software (CVE-2024-11348).
A threat actor targeted low-skilled hackers, known as "script kiddies," with a fake malware builder that secretly infected them with a backdoor to steal data and take over computers. [...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday placed a now-patched security flaw impacting the popular jQuery JavaScript library to its Known Exploited...
A new FBI advisory warned that North Korean IT worker schemes have escalated their activities in recent months to include data extortion
Microsoft says outdated Exchange servers cannot receive new emergency mitigation definitions because an Office Configuration Service certificate type is being deprecated. [...]
The multi-year scheme saw the defendants generate hundreds of thousands in revenue. © 2024 TechCrunch. All rights reserved. For personal use only.
SentinelOne researchers highlighted similarities in the approaches used by the HellCat and Morpheus ransomware groups, suggesting shared infrastructure
Security Information and Event Management (SIEM) systems are now a critical component of enterprise security. Learn more from Smarttech247 about how its VisionX + Splunk solution can help secure...
Check out tips for adopting AI securely from the World Economic Forum. Plus, the EU’s DORA cyber rules for banks go into effect. Meanwhile, a report warns about overprivileged cloud accounts. And...